Author Topic: Write Fault Error fake warning  (Read 3054 times)

0 Members and 1 Guest are viewing this topic.

misskiwii

  • Guest
Write Fault Error fake warning
« on: July 15, 2012, 07:48:26 AM »
Hi there. I was surfing the internet and suddenly about 30 windows popped up saying "System message - Write fault error. A write command during the test has failed to complete". Another window came up saying "System error. Hard disk failure detected. It's highly recommended to run complete HDD scan to prevent loss of personal files." The buttons given were "Scan and repair" and "Cancel and restart" I did not press either and have come here seeking help. Please advise as to what steps I can take.

DrBob

  • Guest
Re: Write Fault Error fake warning
« Reply #1 on: July 15, 2012, 08:34:35 AM »
I had same problem, suspect it was an advert dropped something, crashed browser and came up with same error message.

I could not load Task Manager or Process Explorer to shut the program down (it prevented this), nor could I run Regedit.
But, I was able to get a command prompt up (when I noticed my start menu items were disappearing)
I had a copy of PSTools, so ran PSList (was not blocked) saw a couple of processes I did not recognise (can't recall names sorry), so used PSKill to shut these down.

I was then able to run regedit, task mgr, etc., in regedit I saw it had an entry to run a program in c:\users\ProgramData\ in my case it was called 0TdhCA53ZggWp2.exe only 244k in size. I removed this from regedit.
On another PC found these helpful links:

http://www.smartestcomputing.us.com/topic/46010-how-to-restore-start-menu-and-files-hiddendeleted-by-a-virus/
http://www.bleepingcomputer.com/forums/topic405109.html

sounded very similar.

Not very happy with Avast for letting this through, especially as I have the 3 year spiffy paid up version. But it did block an earlier presumably similar attempt (saw this in Avast logs, this earlier file called (in my case) called twBRGkjhryE3iu.exe was dropped in the c:\users\... \temp\ directory by the browser, was about 333kb in size.

true indian

  • Guest
Re: Write Fault Error fake warning
« Reply #2 on: July 15, 2012, 09:03:58 AM »
No Antivirus is 100% on protection...

@MrBob

if u have the undetected malicious files please send them to virus@avast.com for detection...and remember to have a additional line of security...such as Malwarebytes PRO as no antivirus is 100%


and for people who need help removing this malware...please make own topic and attach the logs in their topic as given here: http://forum.avast.com/index.php?topic=53253.0
« Last Edit: July 15, 2012, 09:05:44 AM by true indian »

DrBob

  • Guest
Re: Write Fault Error fake warning
« Reply #3 on: July 15, 2012, 09:47:22 AM »
BTW further info for anyone else wanting to clean up ...

Though I found these websites very helpful in identification of where to find the missing shortcuts etc.

http://www.smartestcomputing.us.com/topic/46010-how-to-restore-start-menu-and-files-hiddendeleted-by-a-virus/
http://www.bleepingcomputer.com/forums/topic405109.html

note, the instance I got hit with was different, in my version I found only directories …\temp\smtmp\1 and …\temp\smtmp\4, were created .... not 1,2,3,4 as noted in versions in websites above.

The (2) quick launch and (3) taskbar menu entries were actualy still in place, just hidden.

BTW the Trojan/virus had also turned off the entry I always have on, to see hidden/system/operating system files … so I did not immediately spot the greyed out entries.

All the files and folder on my second HDD were hidden too.

Files and folders inside dropbox were hidden, though no other directories were affected (that I’ve noticed yet)


Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Write Fault Error fake warning
« Reply #4 on: July 15, 2012, 02:29:00 PM »
Have you got them all back ?

  • Download RogueKiller  and save it on your desktop
  • Quit all programs
  • Start RogueKiller.exe.
  • Wait until Prescan has finished ... 
  •     Click on Scan
   
 
  • Wait for the end of the scan. 
  • The report has been created on the desktop. 
  • Click on the Delete button.
     
  • The report has been created on the desktop.
  • Next click on the ShortcutsFix   

  • The report has been created on the desktop.
Please post:    All RKreport.txt text files located on your desktop.